Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9.001Nuclei 4.401Metasploit 3.502✓ só verificadosrecentespopularesrisco
5.629 exploits
Referência✓ VexDay Proof
WEBO (Web ORGanizer) 1.0 - 'baseDir' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows r
23RISCO
abrir ↗Referência✓ VexDay Proof
Snort 2.6.1.1/2.6.1.2/2.7.0 - 'fragementation' Remote Denial of Service
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'crack_opendict()' Local Buffer Overflow
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allo
23RISCO
abrir ↗Referência✓ VexDay Proof
Macromedia 10.1.4.20 - 'SwDir.dll' Internet Explorer Stack Overflow Denial of Service
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote
28RISCO
abrir ↗Referência✓ VexDay Proof
ProSysInfo TFTP Server TFTPDWIN 0.4.2 - 'UDP' Denial of Service
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP p
35RISCO
abrir ↗Referência✓ VexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attacke
23RISCO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Kshop 1.17 - 'id' SQL Injection
SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
23RISCO
abrir ↗Referência✓ VexDay Proof
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISCO
abrir ↗Referência✓ VexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject
23RISCO
abrir ↗Referência✓ VexDay Proof
Akarru 0.4.3.34 - 'bm_content' Remote File Inclusion
PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and
23RISCO
abrir ↗Referência✓ VexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RISCO
abrir ↗Referência✓ VexDay Proof
A-Blog 2.0 - 'menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
TagIt! Tagboard 2.1.b b2 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows re
23RISCO
abrir ↗Referência✓ VexDay Proof
PowerPortal 1.3a - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
A-Blog 2.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Krazy Image Hosting 0.7a - 'display.php' SQL Injection
SQL injection vulnerability in display.php in Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a allows remote at
23RISCO
abrir ↗Referência✓ VexDay Proof
MDweb 1.3 - 'chemin_appli' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
ArticleBeach Script 2.0 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
GestArt Beta 1 - 'aide.php?aide' Remote File Inclusion
PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled,
23RISCO
abrir ↗Referência✓ VexDay Proof
mp3SDS 3.0 - '/Core/core.inc.php' Remote File Inclusion
PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabl
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - NAT Helper Components 'ipnathlp.dll' Remote Denial of Service
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISCO
abrir ↗Referência✓ VexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RISCO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RISCO
abrir ↗Referência✓ VexDay Proof
Jinzora 2.6 - '/extras/mt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP
23RISCO
abrir ↗Referência✓ VexDay Proof
phpPC 1.04 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
DivX Player 6.4.1 - DivXBrowserPlugin 'npdivx32.dll' IE Denial of Service
DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.